CVE-2011-2678 describes a local privilege escalation vulnerability in Cisco VPN Client versions 5.0.7.0240 and 5.0.7.0290 on 64-bit Windows platforms. Weak permissions on the cvpnd.exe executable allow an authenticated local attacker to replace it with an arbitrary program, thereby gaining elevated privileges. With a CVSS score of 6.8 (AV:L/AC:L/Au:S/C:C/I:C/A:C), this vulnerability is of medium severity, requiring local access and user authentication for exploitation, but leading to complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0.7.0240CPE matchmatch criteria | cpe:2.3:a:cisco:vpn_client:5.0.7.0240:*:*:*:*:*:*:* | ||
5.0.7.0290CPE matchmatch criteria | cpe:2.3:a:cisco:vpn_client:5.0.7.0290:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.